[ newsletter ]
Stay ahead of Web3 threats—subscribe to our newsletter for the latest in blockchain security insights and updates.
Thank you! Your submission has been received!
Oops! Something went wrong. Please try again.
Explore the details of the October 2024 Radiant Capital hack, a significant exploit in the DeFi space, resulting in a loss of $58 million. Learn about the attack's mechanics, immediate responses, and lessons for future security.
In October 2024, Radiant Capital, a prominent decentralized finance (DeFi) protocol, faced a significant security breach, resulting in an estimated loss of $58 million. This incident marks the second attack on the platform within the year, raising serious concerns about the security of multi-signature wallets and the vulnerabilities inherent in cross-chain protocols.
The exploit was executed through a sophisticated method where the attacker tricked signers into approving malicious transactions. Radiant Capital utilized a 3-of-11 multi-signature scheme, which, while designed for security, inadvertently created a larger attack surface. The attacker employed malware to manipulate the Gnosis Safe wallet interface, making it appear as though legitimate transactions were being processed while actually sending malicious requests for signature.
The attacker successfully transferred control over the protocol’s Pool Provider contract, which manages various lending pools. This allowed them to upgrade the pool contracts to a malicious version, effectively gaining access to user funds.
In the wake of the attack, Radiant Capital and the broader DeFi community took swift action to mitigate further losses:
The Radiant Capital hack underscores the critical need for robust security measures in decentralized finance protocols:
The October 2024 hack of Radiant Capital serves as a stark reminder of the vulnerabilities that exist within the DeFi space. As the industry continues to evolve, it is imperative for protocols to adopt more stringent security measures to protect user assets and maintain trust in decentralized finance systems.